CVE-2019-18397
published 2019-11-13CVE-2019-18397: A buffer overflow in the fribidi_get_par_embedding_levels_ex() function in lib/fribidi-bidi.c of GNU FriBidi through 1.0.7 allows an attacker to cause a denial…
PriorityP337high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
2.18%
80.3th percentile
A buffer overflow in the fribidi_get_par_embedding_levels_ex() function in lib/fribidi-bidi.c of GNU FriBidi through 1.0.7 allows an attacker to cause a denial of service or possibly execute arbitrary code by delivering crafted text content to a user, when this content is then rendered by an application that uses FriBidi for text layout calculations. Examples include any GNOME or GTK+ based application that uses Pango for text layout, as this internally uses FriBidi for bidirectional text layout. For example, the attacker can construct a crafted text file to be opened in GEdit, or a crafted IRC message to be viewed in HexChat.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | fribidi | < fribidi 1.0.7-1.1 (bookworm) | fribidi 1.0.7-1.1 (bookworm) |
| gnu | fribidi | >= 0 < 1.0.7-1.1 | 1.0.7-1.1 |
| gnu | fribidi | >= 0 < 1.0.7-1.1 | 1.0.7-1.1 |
| gnu | fribidi | >= 0 < 1.0.7-1.1 | 1.0.7-1.1 |
| gnu | fribidi | >= 0 < 1.0.7-1.1 | 1.0.7-1.1 |
| gnu | fribidi | 1.0.0 – 1.0.7 | — |
| linux | linux_kernel | >= 0 < 4.15.0-46.49 | 4.15.0-46.49 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
fribidi: buffer overflow in fribidi_get_par_embedding_levels_ex() in lib/fribidi-bidi.c leading to denial of service and possible code execution
vendor_redhat·2019-11-07·CVSS 7.8
CVE-2019-18397 [HIGH] CWE-121 fribidi: buffer overflow in fribidi_get_par_embedding_levels_ex() in lib/fribidi-bidi.c leading to denial of service and possible code execution
fribidi: buffer overflow in fribidi_get_par_embedding_levels_ex() in lib/fribidi-bidi.c leading to denial of service and possible code execution
A buffer overflow in the fribidi_get_par_embedding_levels_ex() function in lib/fribidi-bidi.c of GNU FriBidi through 1.0.7 allows an attacker to cause a denial of service or possibly execute arbitrary code by delivering crafted text content to a user, when this content is then rendered by an application that uses FriBidi for text layout calculations. Examples include any GNOME or GTK+ based application that uses Pango for text layout, as this internally uses FriBidi for bidirectional text layout. For example, the attacker can construct a crafted text file to be opened in GEdit, or a crafted IRC message to be viewed in HexChat.
A heap-based buffe
Ubuntu
FriBidi vulnerability
vendor_ubuntu·2019-11-07
CVE-2019-18397 FriBidi vulnerability
Title: FriBidi vulnerability
Summary: Applications using FriBidi could be made to crash or run programs as your
login if it displayed specially crafted text.
Alex Murray discovered a stack-based buffer overflow when handling a large
number of unicode isolate directives. An attacker could use this to cause a
denial of service or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2019-18397: fribidi - A buffer overflow in the fribidi_get_par_embedding_levels_ex() function in lib/f...
vendor_debian·2019·CVSS 7.8
CVE-2019-18397 [HIGH] CVE-2019-18397: fribidi - A buffer overflow in the fribidi_get_par_embedding_levels_ex() function in lib/f...
A buffer overflow in the fribidi_get_par_embedding_levels_ex() function in lib/fribidi-bidi.c of GNU FriBidi through 1.0.7 allows an attacker to cause a denial of service or possibly execute arbitrary code by delivering crafted text content to a user, when this content is then rendered by an application that uses FriBidi for text layout calculations. Examples include any GNOME or GTK+ based application that uses Pango for text layout, as this internally uses FriBidi for bidirectional text layout. For example, the attacker can construct a crafted text file to be opened in GEdit, or a crafted IRC message to be viewed in HexChat.
Scope: local
bookworm: resolved (fixed in 1.0.7-1.1)
bullseye: resolved (fixed in 1.0.7-1.1)
forky: resolved (fixed in 1.0.7-1.1)
sid: resolved (fixed in 1.0.7-1.1)
GHSA
GHSA-fcm8-q275-jqv2: A buffer overflow in the fribidi_get_par_embedding_levels_ex() function in lib/fribidi-bidi
ghsa_unreviewed·2022-05-24
CVE-2019-18397 [MEDIUM] GHSA-fcm8-q275-jqv2: A buffer overflow in the fribidi_get_par_embedding_levels_ex() function in lib/fribidi-bidi
A buffer overflow in the fribidi_get_par_embedding_levels_ex() function in lib/fribidi-bidi.c of GNU FriBidi through 1.0.7 allows an attacker to cause a denial of service or possibly execute arbitrary code by delivering crafted text content to a user, when this content is then rendered by an application that uses FriBidi for text layout calculations. Examples include any GNOME or GTK+ based application that uses Pango for text layout, as this internally uses FriBidi for bidirectional text layout. For example, the attacker can construct a crafted text file to be opened in GEdit, or a crafted IRC message to be viewed in HexChat.
OSV
CVE-2019-18397: A buffer overflow in the fribidi_get_par_embedding_levels_ex() function in lib/fribidi-bidi
osv·2019-11-13·CVSS 7.8
CVE-2019-18397 [HIGH] CVE-2019-18397: A buffer overflow in the fribidi_get_par_embedding_levels_ex() function in lib/fribidi-bidi
A buffer overflow in the fribidi_get_par_embedding_levels_ex() function in lib/fribidi-bidi.c of GNU FriBidi through 1.0.7 allows an attacker to cause a denial of service or possibly execute arbitrary code by delivering crafted text content to a user, when this content is then rendered by an application that uses FriBidi for text layout calculations. Examples include any GNOME or GTK+ based application that uses Pango for text layout, as this internally uses FriBidi for bidirectional text layout. For example, the attacker can construct a crafted text file to be opened in GEdit, or a crafted IRC message to be viewed in HexChat.
OSV
linux, linux-aws, linux-gcp, linux-kvm, linux-oem, linux-oracle, linux-raspi2 vulnerabilities
osv·2019-03-05·CVSS 5.5
CVE-2018-18397 linux, linux-aws, linux-gcp, linux-kvm, linux-oem, linux-oracle, linux-raspi2 vulnerabilities
linux, linux-aws, linux-gcp, linux-kvm, linux-oem, linux-oracle, linux-raspi2 vulnerabilities
Jann Horn discovered that the userfaultd implementation in the Linux kernel
did not properly restrict access to certain ioctls. A local attacker could
use this possibly to modify files. (CVE-2018-18397)
It was discovered that the crypto subsystem of the Linux kernel leaked
uninitialized memory to user space in some situations. A local attacker
could use this to expose sensitive information (kernel memory).
(CVE-2018-19854)
Jann Horn discovered a race condition in the fork() system call in
the Linux kernel. A local attacker could use this to gain access to
services that cache authorizations. (CVE-2019-6133)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-18397 fribidi: stack based buffer overflow in function fribidi_get_par_embedding_levels_ex() in lib/fribidi-bidi.c leads to denial of service [epel-6]
bugzilla·2019-12-09·CVSS 7.8
CVE-2019-18397 [HIGH] CVE-2019-18397 fribidi: stack based buffer overflow in function fribidi_get_par_embedding_levels_ex() in lib/fribidi-bidi.c leads to denial of service [epel-6]
CVE-2019-18397 fribidi: stack based buffer overflow in function fribidi_get_par_embedding_levels_ex() in lib/fribidi-bidi.c leads to denial of service [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and th
Bugzilla
CVE-2019-18397 fribidi: stack based buffer overflow in function fribidi_get_par_embedding_levels_ex() in lib/fribidi-bidi.c leads to denial of service [fedora-all]
bugzilla·2019-12-09·CVSS 7.8
CVE-2019-18397 [HIGH] CVE-2019-18397 fribidi: stack based buffer overflow in function fribidi_get_par_embedding_levels_ex() in lib/fribidi-bidi.c leads to denial of service [fedora-all]
CVE-2019-18397 fribidi: stack based buffer overflow in function fribidi_get_par_embedding_levels_ex() in lib/fribidi-bidi.c leads to denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelo
Bugzilla
CVE-2019-18397 fribidi: buffer overflow in fribidi_get_par_embedding_levels_ex() in lib/fribidi-bidi.c leading to denial of service and possible code execution
bugzilla·2019-11-05·CVSS 7.8
CVE-2019-18397 [HIGH] CVE-2019-18397 fribidi: buffer overflow in fribidi_get_par_embedding_levels_ex() in lib/fribidi-bidi.c leading to denial of service and possible code execution
CVE-2019-18397 fribidi: buffer overflow in fribidi_get_par_embedding_levels_ex() in lib/fribidi-bidi.c leading to denial of service and possible code execution
A stack buffer overflow in the fribidi_get_par_embedding_levels_ex()
function in lib/fribidi-bidi.c of GNU FriBidi 1.0.0 through 1.0.7
allows an attacker to cause a denial of service or possibly execute
arbitrary code by delivering crafted text content to a user, when this
content is then rendered by an application that uses FriBidi for text
layout calculations. Examples include any GNOME or GTK+ based
application that uses Pango for text rendering, as this internally uses
FriBidi for bidirectional text layout. For example, the attacker can
construct a crafted text file to be opened in GEdit, a crafted IRC
message to be viewed in H
https://access.redhat.com/errata/RHSA-2019:4326https://access.redhat.com/errata/RHSA-2019:4361https://access.redhat.com/errata/RHSA-2020:0291https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=944327https://github.com/fribidi/fribidi/commit/034c6e9a1d296286305f4cfd1e0072b879f52568https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TFS3N6KKXPI6ATDNEUFRSLX7R6BOBNIP/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W5UJRTG32FDNI7T637Q6PZYL3UCRR5HR/https://marc.info/?l=oss-security&m=157322128105807&w=2https://security-tracker.debian.org/tracker/CVE-2019-18397https://security.gentoo.org/glsa/202003-41https://access.redhat.com/errata/RHSA-2019:4326https://access.redhat.com/errata/RHSA-2019:4361https://access.redhat.com/errata/RHSA-2020:0291https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=944327https://github.com/fribidi/fribidi/commit/034c6e9a1d296286305f4cfd1e0072b879f52568https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TFS3N6KKXPI6ATDNEUFRSLX7R6BOBNIP/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W5UJRTG32FDNI7T637Q6PZYL3UCRR5HR/https://marc.info/?l=oss-security&m=157322128105807&w=2https://security-tracker.debian.org/tracker/CVE-2019-18397https://security.gentoo.org/glsa/202003-41
2019-11-13
Published